# Tengri 137 PGP-certifier audit

## Verdict

Two public keys are recovered and their certifications are mathematically
verified against the older `Tengri (137)` UID.  Their public UIDs are
`Noah Mercitalis` and `Varol Tepecik`.  Two other certification issuer
keys remain unavailable in the recorded public-keyserver sweep.

This is context about people who certified a pseudonymous public key. It
is **not** an identity proof for Tengri 137, a proof of an offline meeting,
or evidence that either certifier authored any puzzle artifact.

## Recovered, verified certifications

| Certified UID | Issuer key ID | Public UID | Certification time (UTC) | Result |
|---|---|---|---|---|
| `Tengri (137)` | `040484988228DD98` | Noah Mercitalis | `2017-05-03T02:20:40Z` | `gpg --check-sigs` verifies the certification. |
| `Tengri (137)` | `A49BDCD5BC224010` | Varol Tepecik | `2017-05-07T18:53:27Z` | `gpg --check-sigs` verifies the certification. |

## Certification packets whose issuer keys remain unrecovered

| Certified UID | Issuer key ID | Certification time (UTC) | Public-record result |
|---|---|---|---|
| `Tengri (137)` | `D2FBEC71DB65A36D` | `2017-05-27T01:16:08Z` | No public key material recovered in the recorded multi-keyserver sweep. |
| `Tengri (137)` | `6966D8E21ACC064F` | `2017-11-23T08:30:20Z` | No public key material recovered in the recorded multi-keyserver sweep. |

## What the evidence establishes

The two recovered public keys mathematically verify as third-party 0x10 certifications on the old Tengri (137) UID. Packet records place all four third-party certifications on that UID, rather than on the later Tengri 137 UID.

## What it does not establish

A key certification demonstrates that a private-key holder certified a pseudonymous UID. It does not prove Tengri's legal identity, a meeting, collaboration, authorship by a named person, or that either certifier knew the operator offline.

## Local evidence

- `archive/gaps/tr1-01-files/gpg-check-sigs-tengri-with-two-certifiers.txt` — Saved GnuPG check-sigs output for the two recovered certifier keys; SHA-256 `9e9c685587cf96eef0b1b9c54be7f05117b2ce528eb998ac649bc432e567b929`.
- `archive/gaps/tr1-01-files/gpg-list-packets-tengri.txt` — Packet-level placement, dates, and missing-key issuer details; SHA-256 `25a5cb703f6ebbf5bbdfd2fc964ba852204e2ec94a4a66fde0f6741a0b5ef9f1`.
- `archive/gaps/tr1-01-files/negative-probe-log-two-missing-keys.txt` — Recorded public-keyserver sweep for the two unrecovered issuer keys; SHA-256 `ada40ed14fc9e065737600ecf86c61e725c2492da11acaf1042083f8d6224ad1`.
- `archive/gaps/tr1-01-pgp-certifier-identities.md` — Full research record and provenance; SHA-256 `1607f7ffd363b562119c9dc88588f54e4b487c97a35e9f7f9c8c406a70d45ebc`.
- `archive/gaps/tr1-01-files/tengri-key-refetch.asc` — Refetched Tengri public key carrying the certification packets; SHA-256 `9501a19f980380b0f06788ae46e0809b47d2a51d8679f315561b8b4d459640de`.

## Reproduction

Use a fresh GnuPG home, import the Tengri key plus the two recovered
certifier keys, then run:

```text
gpg --check-sigs 0xD152D6C5666AB731
```

The saved verification log records six good signatures and two signatures
that cannot be checked because those issuer keys are not available. The
public source UIDs are intentionally shortened to names in this public
audit; the original captured key material remains in the cited archive.
